1. Introduction
SentinelOne provides intelligent, data-driven cybersecurity across the enterprise, designed to meet evolving threats. Its Singularity XDR platform uses machine learning and advanced analytics to defend against malware, ransomware, and advanced persistent threats (APTs).
By integrating SentinelOne with Cye Platform, findings and threat data from SentinelOne are automatically ingested and displayed on the Findings page in Cye Platform. This allows you to view, manage, and prioritize these findings within the broader context of your organization’s cyber risk.
2. Prerequisites
Before setting up the integration, make sure you have:
The SentinelOne server URL
A valid SentinelOne API token
Access to the SentinelOne console with admin permissions to create the token
Access to vulnerability data and threat data from the SentinelOne EDR
Cye Platform administrator permissions, required to add the integration
How the Integration Works
The SentinelOne integration follows the same flow as most Cye Platform integrations. It consists of two main parts:
Creating the API credentials in SentinelOne.
Entering those credentials into Cye Platform.
Required IP Addresses
For the integration to work smoothly, you may need to allow traffic from Cye Platform’s servers in your firewall or network configuration. This ensures that Cye Platform can securely connect to your environment and perform scans without being blocked.
Depending on your region and the type of scan, add the following IP addresses:
General IPs:
Europe →
18.198.79.197America →
52.1.10.176,35.171.70.87
IPs for Azure and AWS Scans:
Europe →
18.158.77.90America →
34.206.252.13
In most cases, you only need to add the IPs relevant to your region and use case.
Cye Platform's Group Management and Integrations
This section explains how Cye Platform’s Group Management works in general, and how integrations behave when used in a Group Management setup.
What is Cye Platform's Group Management?
Cye Platform’s Group Management is designed for large enterprises with multiple subsidiaries. It gives you:
A centralized view of cybersecurity risk across the entire organization
Key metrics like exposure, cost of breach, and maturity scores
The ability to switch between subsidiaries and view their individual data
Parent admins and power users can view aggregated and subsidiary-level risk, while detailed findings remain visible only to members of the specific subsidiary
Data that updates in real time
To enable Group Management, contact your CYE Technical Account Manager.
How Integrations Work in Group Management
Here’s the important part:
Integrations are created only at the subsidiary level
Findings from an integration appear only in that subsidiary’s dashboards and reports
Parent companies cannot create integrations — they can only view the aggregated results
Best Practices for Combining Integrations with Group Management
To get the most out of Group Management with integrations, we recommend:
Each subsidiary should create its own integration, using credentials that only grant access to data relevant to that subsidiary
In some cases, it’s useful to also have a dedicated “General” company, which holds findings that apply to the entire enterprise and cannot be tied to a single subsidiary
The parent company then combines these insights and metrics from all subsidiaries and the General company — but remember, integrations cannot be connected directly to the parent company.
3. Configuring on the SentinelOne Side
Create an API Token in SentinelOne
Log in to your SentinelOne management console.
From the left-hand navigation menu, go to:
Settings → Users → Service Users → Actions → Create a New UserEnter a name of your choice. This will serve as the Cye Platform username in SentinelOne.
Click Next.
Assign Permissions
Under Site, select the relevant account and check the Default Site box.
In the Permissions section, assign the Viewer role:
Click Create User.
This generates the API token for the selected site.
Copy the token — you will need to paste it later in Cye Platform.
Copy the Console Domain
Cye Platform also requires the Console Domain from SentinelOne:
Copy the URL from your browser’s address bar while in the SentinelOne console:
Use the domain portion of the URL (as marked in the example provided by SentinelOne).
This value will be entered into the second required field in Cye Platform.
4. Configuring in Cye Platform
Now that you have the required details from SentinelOne, the next step is to configure the integration in Cye Platform.
In Cye Platform, click the gear icon (upper right) to open the Settings page.
From the left-hand tabs, select Integrations and Workflows.
Scroll down to the SentinelOne card and click Add.
A setup page opens where you need to provide the details created in SentinelOne. Two fields are required:
SentinelOne Token – Paste the API token you created in Step 1.1.
SentinelOne Management Console Full Domain – Enter the console domain copied in Step 1.2.
Make sure to enter it without the
http://orhttps://prefix.
You can also enter a name for the integration to help identify it later.
Verify and Save
Click Verify Connection.
If the connection is successful, you will see a green confirmation message.
Click Save to complete the setup.
If the connection fails:
Double-check your network connectivity.
Confirm that you copied the token and console domain correctly.
If needed, generate a new token in SentinelOne and try again.
If you still experience issues, contact our support team at [email protected], or use the support chat bot by clicking the round icon at the bottom of the Cye Platform screen.
Once the connection is verified and saved, the integration is complete.
Note that Data is ingested from SentinelOne every 24 hours.
5. Viewing Results
Integration Added as a Technology Asset
When the integration with SentinelOne is completed successfully, Cye Platform automatically generates a new technology asset with the following details:
Asset type: Vulnerability Management and EDR
Technology name: SentinelOne
Engagement: Integration with external tools
This technology asset is also automatically mapped to the NIST Cybersecurity Framework (CSF).
In Cye Platform, technologies are treated as assets. They represent security tools that support specific NIST subcategories, contribute to your organization’s overall security maturity, and are factored into the maturity level calculation.
Viewing SentinelOne Findings
To focus specifically on SentinelOne data:
Go to the Findings page in Cye Platform.
Use the Sources filter to select SentinelOne.
This allows you to narrow down the findings and view only those ingested from SentinelOne, or combine them with other sources as needed:
Collected Endpoints
Collected endpoints are the data points Cye Platform retrieves directly from SentinelOne. They represent the findings, assets, and threat information that Cye Platform uses to enrich its risk analysis and maturity assessments.
For the SentinelOne integration, Cye Platform collects the following endpoints:
Vulnerability Management
Applications installed on company endpoints – An inventory of software installed across your organization’s devices.
CVEs found in applications – Known security vulnerabilities (Common Vulnerabilities and Exposures) identified in the installed applications.
EDR (Endpoint Detection and Response)
Threats detected by SentinelOne EDR – Alerts and findings from SentinelOne’s detection engine, covering malware, ransomware, and other advanced threats.
In simple terms, these collected endpoints give Cye Platform visibility into both the software vulnerabilities present on your endpoints and the active threats detected by SentinelOne. This combination allows Cye Platform to factor both potential weaknesses and real-world attack activity into its risk quantification.
6. Types of Fetched Entities
Findings and Threat Data
Cye Platform ingests findings and threat data from SentinelOne every 24 hours. This ensures that the information you see in Cye Platform is regularly updated and aligned with your SentinelOne environment.
Wrap-up
In this article, we walked through the full process of integrating SentinelOne with Cye Platform. You learned how to create and configure an API token in SentinelOne, set up the integration in Cye Platform, and verify the connection. We also reviewed how SentinelOne appears in Cye Platform as a technology asset, and how findings and threat data are ingested and displayed every 24 hours. With this integration in place, you can view, filter, and manage SentinelOne findings directly within Cye Platform’s risk and maturity framework.
















